CSSLP · Question #252
In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete…
The correct answer is B. Medium C. High D. Low. FIPS 199, 'Standards for Security Categorization of Federal Information and Information Systems,' defines specific impact levels for information systems.
Question
In 2003, NIST developed a new Certification & Accreditation (C&A) guideline known as FIPS 199. What levels of potential impact are defined by FIPS 199? Each correct answer represents a complete solution. Choose all that apply.
Options
- AModerate
- BMedium
- CHigh
- DLow
How the community answered
(34 responses)- A12% (4)
- B88% (30)
Why each option
FIPS 199, 'Standards for Security Categorization of Federal Information and Information Systems,' defines specific impact levels for information systems.
While 'Moderate' is the precise term used in FIPS 199 for the intermediate impact level, in the context of the provided choices and correct answer, 'Medium' is presented as the intended designation for this level, making 'Moderate' a distinct, unselected option.
Medium represents an intermediate level of adverse effect on organizational operations, organizational assets, or individuals in the event of a security breach.
High signifies a severe or catastrophic adverse effect from a security incident.
Low indicates a limited adverse effect from a security breach. These three categories-Low, Medium (used here as an alternative to Moderate), and High-define the spectrum of potential impact according to FIPS 199 guidelines for categorizing information systems.
Concept tested: NIST FIPS 199 impact levels
Source: https://csrc.nist.gov/publications/detail/fips/199/final
Topics
Community Discussion
No community discussion yet for this question.